Description
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an iCloud folder without authentication.
Problem types
An attacker may be able to turn on sharing of an iCloud folder without authentication
Product status
Any version before 14.7.6
Any version before 15.4
References
seclists.org/fulldisclosure/2025/May/12
seclists.org/fulldisclosure/2025/May/9
seclists.org/fulldisclosure/2025/May/6
support.apple.com/en-us/122373
support.apple.com/en-us/122404
support.apple.com/en-us/122405
support.apple.com/en-us/122717
support.apple.com/en-us/122718
support.apple.com/en-us/122721